Executive brief
A vulnerability was identified in the Linux kernel's Direct Rendering Manager (DRM) subsystem, which manages communication between the operating system and graphics hardware. A race condition could allow a local attacker to trigger a 'use-after-free' error, potentially leading to a system crash or unauthorized access to sensitive memory. This issue primarily affects systems running Linux with active graphics drivers.
Technical details
A race condition exists in the `drm_gem_change_handle_ioctl` function within the DRM GEM (Graphics Execution Manager) component of the Linux kernel. The vulnerability occurs because the ioctl briefly maintains two IDR entries for a single object; a concurrent `gem_close` operation can delete the object and remove one handle while leaving the other dangling. This results in a use-after-free (UAF) when the dangling handle is subsequently dereferenced. The fix involves setting the old handle to NULL before performing the prime swap, ensuring that concurrent operations do not encounter a valid but soon-to-be-deleted object. The issue has been patched in multiple stable branches of the Linux kernel.
Affected products
- Linux Linux Kernel v6.1, v6.6, v6.8
Timeline
- 2026-05-28: advisory: NVD publication date
- 2026-05-08: patched: Initial fix committed to mainline kernel